CVE-2026-48203 is an improper input-validation and header-filtering vulnerability in the Apache Camel camel-solr producer. The producer maps Exchange headers beginning with the non-Camel-prefixed SolrParam. string to Solr request parameters and headers beginning with SolrField. to indexed-document fields. Apache Camel's HTTP header filter blocks the Camel header namespace but allowed these prefixes to pass from an inbound HTTP request into an Exchange. In an HTTP-to-Solr route, an attacker can consequently inject Solr parameters, including parameters capable of causing Solr to make server-side requests, access administrative request handlers, or inject arbitrary indexed-document fields.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a working Java/Spring Boot proof-of-concept for CVE-2026-48203, a header-injection flaw in Apache Camel's camel-solr component. The exploit is not part of a larger exploit framework. The project contains 12 files, with the main logic implemented across Java classes under src/main/java/com/example, plus Docker and Maven files for reproducible deployment. Core structure: Application.java is the Spring Boot entry point. VictimRoute.java defines the vulnerable Camel routes using camel-netty-http on 0.0.0.0:8090 with /index and /search endpoints that forward requests into a solr: producer. SolrSettings.java centralizes Solr host/core/URL construction. SolrReadiness.java waits for the Solr core to become available before use. RawSsrfListener.java opens a raw TCP listener on port 8091 to capture outbound SSRF traffic from Solr. ExploitController.java is the attacker driver exposed through /exploit/attack; it programmatically sends crafted HTTP requests to the victim routes and verifies both field injection and SSRF. Exploit capability 1: document-field injection. The attacker sends a POST to /index with a header like SolrField.injected_role_s: admin-INJECTED. Because affected camel-solr versions treat SolrField.* as trusted control headers and the HTTP boundary filter does not strip them, the header is merged into the SolrInputDocument. The PoC verifies this by querying Solr and checking that the injected field appears in the indexed document. Exploit capability 2: SSRF. The attacker sends a POST to /search with a header like SolrParam.shards: app:8091/ssrf/mycore (or 127.0.0.1:8091/ssrf/mycore locally). Camel copies SolrParam.* headers into Solr request parameters, causing Solr to perform a distributed query against the attacker-specified shard URL. The PoC confirms SSRF by observing an inbound connection on the internal raw TCP listener and recording the first request line. Deployment and purpose: docker-compose.yml launches Solr 9.6 and the app, with SOLR_HOST=solr and SOLR_OPTS=-Dsolr.disable.allowUrls=true to ensure the SSRF path is observable. The Dockerfile packages the built JAR and exposes port 8080. The repository is clearly intended as an authorized research reproducer for a public, fixed vulnerability, demonstrating practical impact rather than merely detecting exposure.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.